AI Governance Institute

How We Track AI Regulation

We start with source documents, check what they say, and publish entries your team can use. Here is our review process.

Verification status

Every directory entry and control has a claim type and review schedule. We review enforcement actions and entries covering the EU, US, UK, and China every 90 days. Other entries have a 180-day cycle. After regulatory changes, reconciled entries include a named reviewer and a change history available on the page.

248
entries and controls on a review cycle
11
with a named reviewer and change history · newest September 20, 2026
0
verification records past their review date

Claim types

Binding requirement
A law or regulation that carries legal obligations and penalties for the parties it covers.
Regulator guidance
How a regulator expects an existing rule to be applied. Persuasive and enforced in practice, but not law in itself.
Voluntary framework
A standard, framework, or public commitment an organization opts into. No legal penalty for non-participation.
AI Governance Institute recommendation
Practical guidance from the AI Governance Institute editorial team. Not a legal requirement.

Directory + controls today: 32 binding, 15 guidance, 36 voluntary, 126 our recommendation.

Daily monitoring

Our automated pipeline scans four areas daily:

  • Regulatory developments include binding and quasi-binding instruments from the EU, US, UK, ISO, OECD, and UNESCO. Asia-Pacific coverage includes China, Japan, Singapore, South Korea, and Australia.
  • Company disclosures include safety commitments, red-team findings, responsible AI reports, incident reports, and policy changes. We cover major technology companies and enterprises using AI.
  • We track foundation model releases and their compliance implications. These include acceptable use policies, safety evaluations, deployment restrictions, and known limitations.
  • We review practitioner analysis from researchers, ethicists, and compliance professionals at think tanks and policy institutes.

Source criteria

Directory policies must have an authoritative primary source:

  • Official government publications and regulatory body websites
  • Standards organization outputs (ISO, NIST, OECD, UNESCO, ITU)
  • Direct company disclosures: press releases, official blog posts, regulatory filings
  • Court decisions and enforcement actions from competent authorities

We do not publish directory policies based on secondary reporting alone. Every entry links directly to its primary source document wherever one is publicly available.

Classification and review

The pipeline assigns each finding to the directory or news feed:

  • Directory entries cover binding regulations, voluntary frameworks, guidelines, and pending legislation. Editors review each entry before publication. They check the source, compare the summary with the document, and verify how we describe compliance implications.
  • News covers enforcement actions, research, company policy changes, and model releases. Reviews focus on factual accuracy and source attribution.

Uncertain findings, major developments, and unfamiliar sources always trigger human review, whatever their category.

Update policy

Directory policies are updated when material changes occur:

  • Amendments or revisions to the underlying instrument
  • New or revised effective dates and compliance deadlines
  • Significant enforcement guidance or regulatory clarification
  • Changes in status (e.g. proposed to enacted, or superseded)

The “verified” date shown on each entry reflects when our editors last reviewed and confirmed the entry. Minor administrative changes that do not affect compliance obligations are not published.

Weekly recap

Every Friday, we publish significant developments from the week with trend analysis and practical guidance for enterprise compliance teams. Editors review the recap before publication. It draws on all items published that week.

Corrections and feedback

We correct errors promptly and note material corrections on the affected entry. Send inaccurate information, outdated entries, missing regulations, or broken links to corrections@aigovernance.com. You can also contact us to suggest coverage.